CVE-2026-55737
Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine. When decoding a LARGE_TUPLE_EXT term, the validation pass decoded_size() in erts/emulator/beam/external.c reads the 32-bit arity field as unsigned (get_uint32()), while the decode pass dec_term() reads the same field as a signed 32-bit integer (get_int32()) into an int. An arity wire value of 0x80000000 passes validation as 2147483648 but decodes as -2147483648, so the subsequent hp += n moves the heap allocation pointer backward. Neither pass enforces the runtime tuple-arity limit MAX_ARITYVAL. The result is an out-of-bounds heap write; in practice the VM detects an impossible heap size and aborts, denying service. The required padding is large when uncompressed but the compressed-ETF envelope shrinks it to a small payload on the wire. This issue affects OTP from OTP 25.0 before 27.3.4.15, 28.5.0.4, and 29.0.4 corresponding to erts from 13.0 before 15.2.7.11, 16.4.0.4, and 17.0.4.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.29%
- CWE
- CWE-195, CWE-787
- Published
- 2026-07-27
- Last modified
- 2026-07-28
Affected products
- Erlang OTP
- Erlang OTP
- Erlang OTP
Weakness type
Related vulnerabilities
- CVE-2026-85441 — MOOS core-moos through 10.4.0 MOOSDB Denial of Service via Negative Serialized String Length
- CVE-2026-18444 — Integer Conversion Vulnerability Resulting in an Out of Bounds Read in NI LabVIEW
- CVE-2026-62959 — Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)
- CVE-2026-55991 — Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
- CVE-2026-49840 — FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing
- CVE-2026-41682 — pupnp: Port truncation via atoi() cast in parse_uri() allows SSRF port confusion
- CVE-2026-26981 — OpenEXR has heap-buffer-overflow via signed integer underflow in ImfContextInit.cpp
- CVE-2025-67897 — In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote...